What Would a Cyber Breach Actually Cost Your Business?
Most business owners picture a cyber attack as a single catastrophic event. In reality, the government's own data shows most incidents cost little — but a meaningful share cost a great deal, and the businesses least prepared are hit hardest. This free estimator uses the official GOV.UK Cyber Security Breaches Survey to give you a realistic, size-specific risk figure in under a minute.
The Real Cost Isn't Just the Ransom
When people think about the cost of a cyber breach, they usually picture a ransom payment. In practice, the biggest costs are often everything around the incident itself: the hours spent responding instead of running the business, the systems that are down, and the clients who lose confidence. Understanding the full shape of that cost is what makes it possible to justify the right level of investment in prevention.
Direct financial loss
Ransom demands, fraudulent payments, and the direct cost of stolen funds or data.
Downtime
Every hour systems are offline is an hour the business isn't trading, billing or serving clients.
Recovery & remediation
Specialist time to investigate, rebuild systems, and close the gap that let the incident happen.
Reputational damage
Client trust, lost referrals, and — for regulated sectors — scrutiny that outlasts the incident itself.
Common Questions
We take the published likelihood of a breach for a business your size and multiply it by the average self-reported cost of the most disruptive breach across all businesses, including the many that cost nothing. It's a simple expected-value calculation, not a prediction — the working is shown on your results screen.
Most reported incidents — a suspicious email that gets caught, a login attempt that gets blocked — never turn into anything costly. The average is pulled upward by a smaller number of businesses that suffer a serious, expensive incident. That's the tail risk this tool is trying to make visible.
Yes. Larger businesses are more likely to detect and report breaches, partly because they have more systems and more monitoring in place, and partly because they're a more attractive target. Smaller businesses often under-report simply because they lack the visibility to know an incident happened at all.
It can, depending on the policy — but insurers increasingly expect baseline controls like MFA and tested backups to be in place before they'll pay out, or they'll price the policy accordingly. Insurance is best treated as a backstop alongside prevention, not a substitute for it.
Phishing remains the most common route in, so enforcing multi-factor authentication on email and admin accounts, combined with regular staff awareness training, addresses the largest share of real-world incidents for the least cost and disruption.
No. This tool gives you a realistic, data-backed starting point based on published national averages for your business size. A formal risk assessment looks at your specific systems, data and processes — this is the conversation starter, not the finished analysis.
Turn This Estimate Into an Action Plan
ITERTECH supports SMEs across Surrey, Hampshire, Berkshire and the wider South East with practical cyber security, from closing the gaps this estimator flags through to full Cyber Essentials certification.